Fakealert Variant

Passing itself off as the usual “mediatubecodec_ver1.1277.0.exe” (do not run this file — it really does not deliver useful codec components for playing videos), this downloader connects back to hxxp://xpantivirussecurity.com, and drops files like “1.exe” that deliver scary popups to alarm our users with false malware detections in an effort to coerce them into paying for a product that they don’t need. Unfortunately, detection has been spotty, with some heuristics performing effectively.